Malware again

This one was tricky because there was a globalroot path and a file name listed as userinit.exe under %systemroot%\system32 which in fact was us?rinit.exe!!! With the Command Prompt, I saw that strange name but not within the Windows Explorer resp. the Windows Explorer showed me that us?rinit.exe as a userinit.exe. Because you cannot use the question mark within file names in Windows it was highly possibly altered via Linux (question marks are allowed there) or some hex editor maybe.

Bad files found onto that system:

userinit.exe (us?rinit.exe), rundll32.exe (malware one), ntload.exe, clerma.dll

Here are some Screenshots:

image[12]

image

image

clip_image001

clip_image001[4]

Advertisements
This entry was posted in Uncategorized and tagged , . Bookmark the permalink.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s